Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.32% | — | Dell Repository ManagerAI | 16/9/2026 | 17/9/2026 | Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Media (5.3) | 0.39% | — | NI Woocommerce Sales ReportAI | 16/9/2026 | 17/9/2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's… | |
| Aplazada | Alta (8.6) | 0.45% | — | NI Woocommerce Sales ReportAI | 16/9/2026 | 17/9/2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Report ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager. Successful attacks… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | Oracle Report ManagerAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Report ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks… | |
| Pendiente de análisis | Alta (8.1) | 0.43% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle Demand Signal RepositoryAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.… | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Redhat Leapp-repositoryAIOracle MysqlAI | 15/9/2026 | 16/9/2026 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that… | |
| Analizada | Baja (3.5) | 0.58% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.51% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.99% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.40% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.7) | 0.84% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (4.8) | 0.40% | — | Microsoft Sharepoint Server | 8/9/2026 | 10/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Sharepoint Server | 8/9/2026 | 10/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |